Jacksonville News 24 Breaking News

collapse
Home / Daily News Analysis / FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

Jul 22, 2026  Twila Rosenbaum  9 views
FortiBleed campaign exposes 75,000 Fortinet firewalls worldwide

Security researchers have uncovered a large-scale credential compromise operation targeting Fortinet firewalls, exposing an estimated 75,000 devices across the globe. Dubbed "FortiBleed," the campaign highlights the persistent risks associated with exposing management interfaces to the internet and using weak or outdated password hashing mechanisms. The attack not only exposed administrative credentials but also provided threat actors with persistent remote access to vulnerable networks.

The campaign was first identified by security researcher Volodymyr Diachenko, who discovered an attacker-controlled list containing potentially working FortiGate passwords. Further investigation by SOCRadar, Hudson Rock, and independent researcher Kevin Beaumont revealed the full scope of the operation. The threat actors systematically collected configuration files from internet-facing Fortinet FortiGate firewalls and then extracted and cracked administrator credentials. The initial access vector that allowed the collection of these configuration files remains unknown, but researchers suspect it may involve unpatched vulnerabilities, misconfigured devices, or brute-force attacks.

Once the configuration files were obtained, the attackers used automated tools to recover administrative passwords. Many of these passwords were stored using older SHA-256 with salt hashing, which is significantly less resistant to offline cracking than modern algorithms. Fortinet introduced PBKDF2-based password hashing for administrator credentials starting in FortiOS versions 7.2.11, 7.4.8, and 7.6.1, but the transition is not automatic. When upgrading from earlier versions, existing administrator passwords remain stored as SHA-256 hashes until the corresponding administrator successfully logs in after the upgrade. This has led to a situation where many organizations continue to rely on weaker password storage without realizing it, making them vulnerable to offline attacks.

The dataset analyzed by researchers contained over 30,791 credentials initially, but further analysis by Kevin Beaumont and Hudson Rock expanded that number to approximately 75,000 credentials, affecting nearly 50% of all internet-facing Fortinet firewalls detected on the popular scanning service Shodan. The compromised devices span 194 countries and cover more than 21,000 unique domains. The top affected countries are India, the United States, and Mexico, which together account for nearly 12,000 compromised credentials. The credential types reveal a strong focus on organization-specific accounts, indicating that the attackers specifically targeted enterprise environments.

The impact of this campaign extends far beyond the initial data compromise. With working administrative credentials, attackers can log in remotely to affected firewalls, gain access to the network, modify security controls, create backdoor accounts, and exfiltrate sensitive data. Because firewalls often serve as the first line of defense for enterprise networks, a compromised firewall can lead to a full network takeover. Benjamin Harris, CEO of watchTowr, noted that modern exploitation often focuses on harvesting credentials that retain value long after the original vulnerability has been patched. This campaign exemplifies that strategy: the credentials were likely accumulated over time by exploiting multiple vulnerabilities in externally facing Fortinet applications, and they remain usable until organizations take corrective action.

Researchers have emphasized that the attack is consistent with the tactics of Russian-speaking threat actors, based on tooling and targeting choices observed in the infrastructure used to store and process the stolen data. Attribution is still ongoing, but the operational fingerprints point to an organized group with significant resources. The automation involved in collecting, cracking, and testing credentials suggests a well-established operation designed to maximize the number of compromised devices.

For organizations using Fortinet firewalls, the recommended response is to assume that any credentials contained in exposed configuration files have been compromised. Immediate steps include rotating all administrative and VPN passwords, enforcing multi-factor authentication (MFA) on all administrative and VPN access, and restricting internet access to management interfaces. Furthermore, organizations should review their devices for signs of unauthorized access, such as unfamiliar admin accounts, altered configurations, or unexpected VPN sessions.

Upgrading to supported FortiOS versions that implement PBKDF2-based password hashing is critical. After upgrading, all administrators must log in to the firewall at least once to trigger the conversion of their password hash from SHA-256 to PBKDF2. Alternatively, a super-admin account can be used to manually update passwords for all accounts. Organizations should also review their password policies to ensure that administrators use complex, unique passwords that are resistant to offline cracking. Reusing passwords across multiple devices or services increases the risk of further compromise.

The FortiBleed campaign serves as a stark reminder of the importance of securing network infrastructure. Exposing firewall management interfaces to the internet is a high-risk practice, even with strong authentication measures in place. Attackers are increasingly focusing on network devices as entry points because they often have privileged access and are not subjected to the same level of monitoring as servers and endpoints. Regular security assessments, vulnerability patching, and adherence to best practices for credential management are essential to defend against such campaigns.


Source: Network World News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy